3CX DesktopApp Cascading Supply Chain Attack (Lazarus Group)
Key Facts
- Legal Status: INVESTIGATION in National Cyber Security Centre & Mandiant Forensic Reports.
- Primary Target Sector: Telecommunications & Enterprise VoIP.
- Documented Financial Loss: $85.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Telecommunications & Enterprise VoIP networks. North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.
Operational & Financial Fallout
Global enterprise security containment, code signing certificate revocations, and application rebuilds. Impacted Telecommunications & Enterprise VoIP infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Telecommunications & Enterprise VoIP networks. North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.
Adversary Kill Chain Flow
2 Documented PhasesOperatives secured access to victim infrastructure within the Telecommunications & Enterprise VoIP sector.
North Korean state-sponsored threat group Lazarus compromised VoIP communications software provider 3CX, injecting malware into digitally signed Windows and macOS builds of 3CXDesktopApp downloaded by over 600,000 corporate customers, in the first documented case of one software supply chain compromise directly enabling a second downstream supply chain breach.
Global enterprise security containment, code signing certificate revocations, and application rebuilds. Impacted Telecommunications & Enterprise VoIP infrastructure and associated victim operations.
Procedural & Incident Timeline
3CX signs and distributes trojanized desktop application update to global customers.
CrowdStrike and SentinelOne publicly flag 3CXDesktopApp as malicious.
Mandiant reveals initial compromise stemmed from employee downloading infected Trading Technologies software.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1195.002 | "Malicious code was compiled into ffmpeg.dll and d3dcompiler_47.dll, which were digitally signed by 3CX legitimate Apple and Windows certificates." | Mandiant Technical Report: 3CX Software Supply Chain Compromise | reviewed | |
| T1071.001 | Web Protocols Command and Control | "The backdoored desktop client pulled encrypted icon files containing base64 command-and-control server domains from public GitHub repositories." | CISA Alert AA23-090A | reviewed |